CVE-2024-39934: Robocorp Rcc Shared Holotree Enabled

Enabling the shared holotree feature in Robocorp RCC (via `holotree shared --enable`) configures Python environments with overly permissive access rights. This enables unprivileged local users to edit the environment files, potentially leading to local privilege escalation if the environment is later accessed or executed by a higher-privileged user or system

Provally CuratedPublic repositoryHighMedium confidenceVerifiedApache-2.0Rust
greprules fetch cve-2024-39934-robocorp-rcc-shared-holotree-enabled --engine opengrep

Description

Enabling the shared holotree feature in Robocorp RCC (via `holotree shared --enable`) configures Python environments with overly permissive access rights. This enables unprivileged local users to edit the environment files, potentially leading to local privilege escalation if the environment is later accessed or executed by a higher-privileged user or system